Forum Home
Press F1
 
Thread ID: 60031 2005-07-20 10:14:00 redirecting to porn site bartsdadhomer (80) Press F1
Post ID Timestamp Content User
373853 2005-07-20 10:35:00 I assume you ran all the tests in safe mode? Myth (110)
373854 2005-07-20 10:36:00 Sure a reinstall will / should fix it for good but it'd sure be nice to know how it's done.

Trciky in the extreme. I've been hit by lots of crud but always managed to get rid of it. Sometimes from tips from you helpful people here at Pressf1...........m :)
mark c (247)
373855 2005-07-20 10:37:00 Have you cleared th autocomplete entries - Internet options/ Content/Autocomplete

Tried another browser?

Yep & Nope I thought about trying firefox but it seems the easy way out, I hate to admit defeat

And I did run some of them in safemode
bartsdadhomer (80)
373856 2005-07-20 10:40:00 can you post the HJT log please :) tweak'e (69)
373857 2005-07-20 10:59:00 can you post the HJT log please :)
Can't till tomorrow, but trust me I've been over it with a fine tooth comb several times and there is nothing untoward
But I'll post it tomorrow anyway
bartsdadhomer (80)
373858 2005-07-20 11:04:00 Makes me wish i could get in front of her for an hour,Love a good puzzle. Metla (12)
373859 2005-07-20 11:06:00 Makes me wish i could get in front of her for an hour,Love a good puzzle.
Exactly the reason I don't want to format or use another browser, I wanna nail the sucker
bartsdadhomer (80)
373860 2005-07-20 11:42:00 it is better to get the sucker. format fixes it, but it could easily come back the next day. a lot of younger techs i've come across do that at the drop of a pin. then i'm called in cos they didn't do any backups or backed up outlook express, but the emails are on ms outlook, or forgot about the 20gb of mp3s somewhere, hehehe. quarry (252)
373861 2005-07-20 12:02:00 try this

do a whois or ping on the redirect url
write down the ip

Then search the machine registry for both url and ip

Also search the entire machine for files containing those (url, ip) strings
include system and hidden files

happy hunting
beama (111)
373862 2005-07-20 12:15:00 Downloaded Programme File in WNNT folder (ActiveX objects, Java, etc)?

Add/Remove Programs? (not too obvious is it)

Not got a foreign protocol in Network Properties or something disguised as a driver?

Run system file checker?
Murray P (44)
1 2 3 4 5